element-hq / element-hq/element-android
RiotX doesn't make it obvious why or how to verify
- Dominant language
- Kotlin
- Stars
- 3.7k
- Forks
- 917
- PR merge metrics
- No merged PRs in 30d
Description
I recently installed RiotX on my brother-in-law's phone, and taught him its basics. He managed to open a one-to-one chat (which are now encrypted by default) with his sister.
They both got a black shield icon on the room, and a message telling them that the room's contents were encrypted and that they should "learn more" and "verify each other".
However, the message didn't tell them how or why to do it. As a result, they never bothered to verify each other and the shield stayed black.
To avoid that, I think that the "messages are encrypted" warning should also tell you, as clearly as possible, why you should verify them; something like "messages are encrypted, but you must verify users if you want to be sure that nobody else is listening".
This message should also appear in the "security" section of the room information screen; there is currently an informational message there, but it doesn't tell you why you should verify anyone.
Additionally, the first time that an unverified user sends a message, an additional message should appear and encourage you to verify that user. Something like "verify this user to be sure that nobody else is listening" and a button that takes you directly to the verify screen.
Contributor guide
Assessment
This issue has not been assessed yet.